Component: ike1
101 changelog entries across 67 version(s)
Releases by channel (stacked)
- added ChaCha20-Poly1305 ESP encryption support;
- added ChaCha20-Poly1305 ESP encryption support;
- fixed an issue where policies could be released too early before re-acquisition;
- fixed an issue where policies could be released too early before re-acquisition;
- removed unsupported NAT-D drafts with invalid payload numbers;
- removed unsupported NAT-D drafts with invalid payload numbers;
- fixed invalid key length on phase1 negotiation;
- log an error when non-RSA keys are being used;
- fixed invalid key length on phase1 negotiation;
- fixed Phase 1 when using aggressive exchange mode (introduced in v7.10);
- log an error when non-RSA keys are being used;
- fixed Phase 1 when using aggressive exchange mode (introduced in v7.10);
- improved service stability when handling non-RSA keys (introduced in v7.9beta4);
- disallow "remote-id" setting for identity;
- fixed XAuth responder trying to recreate phase 1;
- improved expired IPsec-SA processing;
- disallow "remote-id" setting for identity;
- fixed XAuth responder trying to recreate phase 1;
- improved expired IPsec-SA processing;
- fixed "my-id=address" parameter usage together with certificate authentication;
- fixed 'rsa-signature-hybrid' authentication method;
- fixed memory leak on multiple CR payloads;
- fixed policy update with and without mode configuration;
- rekey phase 1 as responder for Windows initiators;
- fixed 'rsa-signature-hybrid' authentication method;
- fixed memory leak on multiple CR payloads;
- allow using "my-id" parameter with XAuth;
- allow using "my-id" parameter with XAuth;
- fixed "my-id=address" parameter usage together with certificate authentication;
- improved stability when performing policy lookup on non-existant peer;
- allow using "my-id" parameter with XAuth;
- fixed policy update with and without mode configuration;
- rekey phase 1 as responder for Windows initiators;
- added error message when specifying "my-id" for XAuth identity;
- added support for "UNITY_DEF_DOMAIN" and "UNITY_SPLITDNS_NAME" payload attributes;
- do not try to keep phase 2 when purging phase 1;
- improved policy lookup with specific protocol;
- improved stability when performing policy lookup on non-existant peer;
- rekey phase 1 rekeying as responder for Windows initiators;